Agenda for Misuse Detection Project Meeting
Tuesday 23-September-97, 10am - 10:30am

Review agenda. Select a timekeeper.
Hashii Marks (aka Audit Performance measures) (0:10) Chris
    Kathy will be working 10 hrs/week during Fall Qtr.
    This is about 100 hrs minus overhead (meetings etc.)
    She will investigate the performance overhead imposed
    by auditing, primarily NT, but also BSM if necessary.

Polymorphic Viruses (0:05) Kathy
    Kathy will wrap this effort week

File relationship (0:10) Scott
    Scott can contact MEZ at open group to get a copy
    of domain Type enforcement for NT.

Topics for next agenda (0:10)
    schedule meeting with Susan
    schedule time slot for weekly meeting
    statement of work

23-September-97 Meeting Notes, 10am - 10:30am

Attendees: Chris, Kathy, Scott

Hashii Marks (aka Audit Performance measures) (0:10) Chris
    Kathy will be working 10 hrs/week during Fall Qtr.
    This is about 100 hrs minus overhead (meetings etc.)
    She will investigate the performance overhead imposed
    by auditing, primarily NT, but also BSM if necessary.

    Since it is harder to measure CPU performace, we should
    concentrate instead on disk/storage sizes. We want to compile a
    list of all the event record sizes. This may not be a
    straightforward list of sizes, but a set of parameterized
    formulas.

    For a set of "typical" transactions, we want to compile a set of
    audit records that are produced modulo the audit flags that are
    active.  Here are some typical transactions:

    netscape browsing a new page every 15 seconds.
    Word editing a 40 page document
    printing a 5, 10, or 50 page document
    Telnet
    A WWW server (IIS) with 100 hits / minute
    compiling a program in C++
    a database program (e.g., Access) running various operations (TBD)

    We want to know the frequency and distribution of event types
    sizes of events.
    Any other measures which may characterize the transactions.

    Since Event Viewer is lame, we plan to use Crystal Reports.

Polymorphic Viruses (0:05) Kathy
    Kathy will wrap this effort week

File relationship (0:10) Scott
    Scott can contact MEZ at open group to get a copy
    of domain Type enforcement for NT.

Topics for next agenda (0:10)
    schedule meeting with Susan
    schedule time slot for weekly meeting
    statement of work